Loading HuntDB...

GHSA-xvq6-h898-wcj8

GitHub Security Advisory

Mattermost denial of service vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

Affected Packages

Go github.com/mattermost/mattermost-server/v6
Affected versions: 0 (fixed in 7.8.12)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 8.0.0 (fixed in 8.0.4)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 8.1.0 (fixed in 8.1.3)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.0.0 (fixed in 9.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-xvq6-h898-wcj8
Published
November 6, 2023 6:30 PM
Last Modified
November 8, 2023 2:53 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost-server/v6
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.